Drop the extension, and give the test suite a front door
Phase 6, the last of the fresh-install spec. 159 scripts lose their .sh: 110 contracts, 47 Vicinae commands, 2 compositor contracts. A shebang and the executable bit already select the interpreter. The extension only ever added something that had to stay in sync, and the rename proved the point twice over in the space of an hour. The spec's stated risk was Vicinae's script discovery. One script was renamed and reloaded on its own before the other 46 followed; it came back as scripts:panama.capture and all 47 resolve. What the probe turned up instead is that the extension was never only a filename: Vicinae's command IDs embed it, so every ID changed. Nothing in this repository refers to them, so nothing breaks. The only trace is Vicinae's metadata.json, whose visited map had two Panama entries that are now orphaned -- two commands lost their usage ranking and will earn it back. Worth knowing before anyone renames these again on a machine that has a keybind pointing at one. Rewriting the references by exact filename missed two things it structurally could not see: a name built from a variable, settings-$page.sh, and a glob, -name '*.sh'. Both were in the contract that counts the generated commands, which promptly reported 47 expected and 0 found. The mechanical part of a rename is the part that looks finished. The three subcommands. panama doctor fronts a health check that already existed and already ran at the end of every install but could not be reached from a terminal. panama upgrade re-runs the installer from anywhere. panama test runs the suite, which had no entry point at all -- 121 files that were the main safety net in this repository and were invisible in it. Writing that runner found three tests nothing was running. calendar_agenda_bridge_test, home_assistant_bridge_test and kdeconnect_bridge_test are unittest suites without the executable bit, so no contract invoked them and the first draft of the runner skipped them silently. All three pass, and have passed unobserved for weeks. The runner collects *_test.py as well now, because a runner with a blind spot is worse than no runner for the same reason a dependency checker with one is: it reports PASS. Six worktrees pruned. Each was re-checked rather than trusted to the spec's list, and two needed it: panama-commands is not on feat/panama-commands but on feat/gnome-tweaks-parity, and fix/panama-displays-review reads [ahead 3] -- ahead of its remote, not of main, with every commit patch-equivalent to landed work. roadmap-completion stays; it has five commits that are genuinely unlanded. The branches are left alone: pruning a worktree costs nothing, deleting a branch is a decision. 121 contracts pass. Claude-Session: https://claude.ai/code/session_01NvgBuSWB5sE43yWmg21ozj
This commit is contained in:
Executable
+94
@@ -0,0 +1,94 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
# Managing a LOCAL user account (see online-accounts for the other kind).
|
||||
#
|
||||
# Managing an account must not leak the credential it sets, and must not let
|
||||
# someone lock themselves out of their own machine.
|
||||
#
|
||||
# Nothing here creates, deletes, or modifies a real account. It reads the
|
||||
# account state, which is safe, and exercises the refusals, which are the part
|
||||
# that has to hold.
|
||||
|
||||
set -uo pipefail
|
||||
|
||||
repo_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
|
||||
helper="$repo_dir/config/dot/quickshell/scripts/panama-users"
|
||||
service="$repo_dir/config/dot/quickshell/services/UserAccounts.qml"
|
||||
page="$repo_dir/config/dot/quickshell/modules/settings/UsersPage.qml"
|
||||
|
||||
fail() {
|
||||
printf 'user accounts contract: %s\n' "$1" >&2
|
||||
exit 1
|
||||
}
|
||||
|
||||
for path in "$helper" "$service" "$page"; do
|
||||
[[ -r "$path" ]] || fail "missing $path"
|
||||
done
|
||||
[[ -x "$helper" ]] || fail 'panama-users is not executable'
|
||||
|
||||
# ── A new password never reaches a command line ─────────────────────────────
|
||||
# argv is world-readable through /proc, so a password passed as an argument is
|
||||
# published to every process on the machine. It is read from stdin, and the
|
||||
# hashing step reads ITS stdin too, so the cleartext exists only inside these
|
||||
# two processes.
|
||||
password_body="$(sed -n '/^def set_password/,/^def /p' "$helper")"
|
||||
[[ -n "$password_body" ]] || fail 'set_password is missing'
|
||||
grep -q 'sys.stdin.buffer.read()' <<<"$password_body" \
|
||||
|| fail 'the new password is not read from stdin'
|
||||
grep -q 'input=secret' <<<"$password_body" \
|
||||
|| fail 'the password is not handed to the hashing tool on stdin'
|
||||
grep -qE '"openssl", "passwd"[^]]*secret' <<<"$password_body" \
|
||||
&& fail 'the password appears in the hashing command line'
|
||||
grep -qE '^\s*print\((secret|hashed)' <<<"$password_body" \
|
||||
&& fail 'the password or its hash is printed'
|
||||
|
||||
# The service must not hold one either, beyond the moment it hands it over.
|
||||
grep -q 'stdinEnabled' "$service" \
|
||||
|| fail 'the service does not write the password over stdin'
|
||||
grep -qE 'command:.*set-password.*password' "$service" \
|
||||
&& fail 'the service puts the password in the command line'
|
||||
grep -q 'root.pendingPassword = ""' "$service" \
|
||||
|| fail 'the service never clears the password it was holding'
|
||||
|
||||
# ── Refusals that keep a machine administrable ──────────────────────────────
|
||||
delete_body="$(sed -n '/^def delete_user/,/^def /p' "$helper")"
|
||||
grep -q 'You cannot delete the account you are signed in to' <<<"$delete_body" \
|
||||
|| fail 'the helper would delete the account running it'
|
||||
grep -q 'only administrator' <<<"$delete_body" \
|
||||
|| fail 'the helper would remove the last administrator, leaving nobody able to administer the machine'
|
||||
|
||||
# The page must not offer to change the type of the only administrator either.
|
||||
grep -q 'administratorCount <= 1' "$page" \
|
||||
|| fail 'the page offers to demote the only administrator'
|
||||
|
||||
# ── Deleting is confirmed, and says what it destroys ────────────────────────
|
||||
grep -q 'confirmingRemoval' "$page" \
|
||||
|| fail 'the page deletes an account without a confirmation step'
|
||||
grep -q 'This cannot be undone' "$page" \
|
||||
|| fail 'the page does not say that deleting an account destroys their files'
|
||||
|
||||
# ── The snapshot is real, and reports no secrets ────────────────────────────
|
||||
command -v jq >/dev/null 2>&1 || { printf 'user accounts contract: SKIP (no jq)\n'; exit 0; }
|
||||
snapshot="$("$helper" snapshot 2>/dev/null)" || fail 'snapshot failed'
|
||||
jq -e '.users | type == "array" and length > 0' <<<"$snapshot" >/dev/null \
|
||||
|| fail 'no accounts were reported'
|
||||
jq -e '[.users[] | (.userName | length > 0)] | all' <<<"$snapshot" >/dev/null \
|
||||
|| fail 'an account has no user name'
|
||||
jq -e '.currentUser | length > 0' <<<"$snapshot" >/dev/null \
|
||||
|| fail 'the snapshot does not say which account is signed in'
|
||||
|
||||
offenders="$(jq -r '[paths | map(tostring) | join(".")] | map(select(test("(password|secret|hash)$";"i"))) | join(", ")' <<<"$snapshot")"
|
||||
[[ -z "$offenders" ]] || fail "the snapshot carries credential-shaped fields: $offenders"
|
||||
|
||||
# System accounts are not people and must not be offered for management.
|
||||
jq -e '[.users[] | .uid >= 1000] | all' <<<"$snapshot" >/dev/null \
|
||||
|| fail 'a system account is listed as a manageable user'
|
||||
|
||||
# ── Input validation ────────────────────────────────────────────────────────
|
||||
for bad in "root; rm -rf /" "../escape" "UPPER" ""; do
|
||||
result="$("$helper" set-real-name "$bad" "Test" 2>/dev/null | jq -r '.error // ""')"
|
||||
[[ -n "$result" ]] || fail "the helper accepted \"$bad\" as a user name"
|
||||
done
|
||||
|
||||
printf 'user accounts contract: PASS (%d account(s), credentials never on a command line)\n' \
|
||||
"$(jq '.users | length' <<<"$snapshot")"
|
||||
Reference in New Issue
Block a user